CVE-2026-45409: Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as "\u0660" N or "\u30fb" N + "\u6f22" utilize the validcontexto function prior to length rejection, and for high values of N will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the idna.encode() function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the idna.encode() function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.
Other sources
This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. Payloads such as "\u0660" N or "\u30fb" N + "\u6f22" utilize the validcontexto function prior to length rejection, and for high values of N will take a long time to process.
Impact A specially crafted argument to the idna.encode() function could consume significant resources. This may lead to a denial-of-service.
Patches Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support).
Workarounds Domain names cannot exceed 253 characters in length, if this length limit is enforced prior to passing the domain to the idna.encode() function it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/idnato a version that resolves this vulnerability.Fixed in 3.15 - Upgrade
Upgrade
debian/python-idnato a version that resolves this vulnerability.Fixed in 3.10-1+deb13u1Fixed in 3.18-1 - Configuration
Enforce the domain name length limit (maximum 253 characters) in the higher-level application prior to calling idna.encode(), so that long inputs are rejected before further IDNA processing.
Python IDNA library (idna.encode / IDNA processing) pre-validation of domain length before calling idna.encode() = Reject/limit domain names to a maximum of 253 characters before passing to idna.encode() - Configuration
Ensure/enable behavior that rejects long inputs early (as soon as practicable) before invoking additional processing functions such as valid_contexto to minimize resource consumption.
Python IDNA library (idna.encode) timing of length rejection = Reject long inputs as soon as practicable prior to any further processing
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45409?
CVE-2026-45409 has a risk rating of 22, indicating a significant vulnerability.
How do I fix CVE-2026-45409?
To fix CVE-2026-45409, ensure that the application correctly implements input validation to reject excessively long payloads.
What software is affected by CVE-2026-45409?
CVE-2026-45409 affects the pip/idna library.
What is the main issue with CVE-2026-45409?
CVE-2026-45409 involves improper input validation that allows for processing excessively long payloads.
How does CVE-2026-45409 relate to CVE-2024-3651?
CVE-2026-45409 is the same issue as CVE-2024-3651, where the original remediation was incomplete.